2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-3714HIGH8.8The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec...
CVE-2023-3713HIGH8.8The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec...
CVE-2023-3459HIGH7.2The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to...
CVE-2023-38434HIGH7.5xHTTP 72f812d has a double free in close_connection in xhttp.c via a malformed HTTP request method.
CVE-2023-34143HIGH8.1Improper Validation of Certificate with Host Mismatch vulnerability in Hitachi Device Manager on Windows, Linux (Device ...
CVE-2023-34142HIGH7.5Cleartext Transmission of Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manage...
CVE-2023-31998HIGH7.5A heap overflow vulnerability found in EdgeRouters and Aircubes allows a malicious actor to interrupt UPnP service to sa...
CVE-2023-37479HIGH7.5Open Enclave is a hardware-agnostic open source library for developing applications that utilize Hardware-based Trusted ...
CVE-2023-3724HIGH8.8If a TLS 1.3 client gets neither a PSK (pre shared key) extension nor a KSE (key share extension) when connecting to a m...
CVE-2023-37476HIGH7.8OpenRefine is a free, open source tool for data processing. A carefully crafted malicious OpenRefine project tar file ca...
CVE-2023-38405HIGH7.5On Crestron 3-Series Control Systems before 1.8001.0187, crafting and sending a specific BACnet packet can cause a crash...
CVE-2023-38404HIGH8.8The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attac...
CVE-2023-38403HIGH7.5iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
CVE-2023-34141HIGH8A command injection vulnerability in the access point (AP) management feature of the Zyxel ATP series firmware versions ...
CVE-2023-34139HIGH8.8A command injection vulnerability in the Free Time WiFi hotspot feature of the Zyxel USG FLEX series firmware versions 4...
CVE-2023-34138HIGH8A command injection vulnerability in the hotspot management feature of the Zyxel ATP series firmware versions 4.60 throu...
CVE-2023-33012HIGH8.8A command injection vulnerability in the configuration parser of the Zyxel ATP series firmware versions 5.10 through 5.3...
CVE-2023-33011HIGH8.8A format string vulnerability in the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmw...
CVE-2023-37475HIGH7.5Hamba avro is a go lang encoder/decoder implementation of the avro codec specification. In affected versions a well-craf...
CVE-2023-34669HIGH7.5TOTOLINK CP300+ V5.2cu.7594 contains a Denial of Service vulnerability in function RebootSystem of the file lib/cste_mod...
CVE-2023-28767HIGH8.8The configuration parser fails to sanitize user-controlled input in the Zyxel ATP series firmware versions 5.10 through ...
CVE-2023-3615HIGH8.1Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a ne...
CVE-2023-3591HIGH8.2Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created.
CVE-2023-3590HIGH7.5Mattermost fails to delete card attachments in Boards, allowing an attacker to access deleted attachments.
CVE-2023-3581HIGH8.1Mattermost fails to properly validate the origin of a websocket connection allowing a MITM attacker on Mattermost to acc...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now